Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-4163

Upgrade spring framework to 5.3.26 and jettison to 1.5.4

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • 2.2.0
    • 3.0.0
    • admin
    • None
    • Important

    Description

      CVE-2023-20861:- In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

      CVSSv3 Score:- 6.5(Medium)

      Affected Version:- upto 5.2.22(including), 5.3.0(including) to 5.3.25(including), 6.0.0(including) to 6.0.6(including)

      https://nvd.nist.gov/vuln/detail/CVE-2023-20861

      Attachments

        Issue Links

          Activity

            People

              pradeep Pradeep Agrawal
              pradeep Pradeep Agrawal
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: